TY - JOUR
T1 - Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation
AU - Louck, Yedidel
AU - Dvir, Amit
AU - Stulman, Ariel
N1 - Just Accepted
PY - 2026/3/1
Y1 - 2026/3/1
N2 - Multi-agent systems (MAS) powered by artificial intelligence (AI) are increasingly foundational to complex, distributed workflows. Yet, the security of their underlying communication protocols remains critically under-examined. This paper presents the first empirical, comparative security analysis of three leading communication standards: Google’s Agent-to-Agent (A2A) protocol, the SDK-based Agent Communication Protocol (ACP), and the blockchain-integrated CORAL protocol. Using a 14 point vulnerability taxonomy, we systematically assess their defenses across authentication, authorization, integrity, confidentiality, and availability. Our results reveal a pronounced security dichotomy: CORAL exhibits a robust architectural design, particularly in its transport-layer message validation and session isolation, but suffers from critical implementation-level vulnerabilities, including authentication and authorization failures at its SSE gateway. Conversely, ACP’s architectural flexibility, most notably its optional JWS enforcement, translates into high-impact integrity and confidentiality flaws. We contextualize these findings within current industry trends, highlighting that existing protocols remain insufficiently secure. Finally, we propose the Secure Transport Envelope (STE), a formalized hybrid architecture that combines CORAL’s transport locking with ACP’s cryptographic integrity, offering a concrete blueprint for the next generation of secure agent communication.
AB - Multi-agent systems (MAS) powered by artificial intelligence (AI) are increasingly foundational to complex, distributed workflows. Yet, the security of their underlying communication protocols remains critically under-examined. This paper presents the first empirical, comparative security analysis of three leading communication standards: Google’s Agent-to-Agent (A2A) protocol, the SDK-based Agent Communication Protocol (ACP), and the blockchain-integrated CORAL protocol. Using a 14 point vulnerability taxonomy, we systematically assess their defenses across authentication, authorization, integrity, confidentiality, and availability. Our results reveal a pronounced security dichotomy: CORAL exhibits a robust architectural design, particularly in its transport-layer message validation and session isolation, but suffers from critical implementation-level vulnerabilities, including authentication and authorization failures at its SSE gateway. Conversely, ACP’s architectural flexibility, most notably its optional JWS enforcement, translates into high-impact integrity and confidentiality flaws. We contextualize these findings within current industry trends, highlighting that existing protocols remain insufficiently secure. Finally, we propose the Secure Transport Envelope (STE), a formalized hybrid architecture that combines CORAL’s transport locking with ACP’s cryptographic integrity, offering a concrete blueprint for the next generation of secure agent communication.
U2 - 10.1145/3803431
DO - 10.1145/3803431
M3 - ???researchoutput.researchoutputtypes.contributiontojournal.article???
JO - ACM Transactions on AI Security and Privacy
JF - ACM Transactions on AI Security and Privacy
ER -